A man hands his keys to a valet outside a downtown restaurant. He gives his name and his cell number, and then the valet taps them into an app. That app kept his license plate as well. Months later, security researchers found thousands of those plate records sitting on the open web, readable by anyone who knew the address. Meanwhile, he was not told, because there was no single company to tell him. The Supabase data leak works like that: the harm arrives through an app you used once and forgot.
Confirmation: reported by UpGuard Research on September 25, 2026, and covered the same day by TechCrunch. The individual apps involved have not issued notices.
What happened in the Supabase data leak
Supabase is a hosting service developers use to stand up a database quickly. In particular, it is popular with “vibe-coded” apps — software written largely by an AI assistant from a plain-language prompt.
So UpGuard scanned the internet for those databases. In total, it found 16,326 with publicly readable tables, which the firm calls the largest study of its kind. Over half of them appear to hold personal information about real people. In addition, a smaller share exposes passwords and authentication tokens, and in rare cases, partial payment data.
One point matters before anything else. Supabase itself was not hacked. The company’s own dashboard turns on the protective setting by default, and its chief information security officer says projects are secure by default, with security a shared responsibility. In short, what leaked, leaked out of the apps built on top.
Why it happened: a setting the AI did not turn on
Supabase uses Row Level Security, a rule that decides which rows a given visitor may read. For example, create a table through the Supabase dashboard and that rule is switched on for you.
But AI coding tools often write raw SQL instead. Because of that, raw SQL creates the table with the rule off. So the app works, the demo looks great, and the database answers questions from anyone on the internet who asks politely. Nobody chose that. Instead, the gap sits between two interfaces, and the person shipping the app rarely sees it.
This is not the first sign of the pattern. UpGuard notes that in February 2026, Wiz found a Supabase behind an AI-agent social site leaking 35,000 email addresses and 1.5 million API tokens. Similarly, earlier scans by Escape and Red Access found hundreds of leaking databases across a few thousand apps each.
What the Supabase data leak exposed, and what someone can do with it
UpGuard confirmed live leaks touching services in the United States, Canada, India, the Philippines and Africa. The examples are specific, and for that reason they are worth your time.
- Email addresses. 4,560 of the exposed addresses sat on third-party corporate domains, about 11 percent of the total. An address plus context is the raw material for a message you will believe.
- Names, home addresses and phone numbers. Together these let a stranger pass a “confirm your identity” question, or instead send a text about a parking fine that quotes your real plate.
- Passwords. If it is reused anywhere, a leaked password becomes a key to your other accounts. That is credential stuffing, and it is cheap to run at scale.
- Authentication tokens. A token can act as you without a login, for as long as it stays valid. Rotating your sign-in is therefore the fix.
- Private conversations. One exposed database held chat logs from an adult streaming site. Another belonged to a government consulate.
For a fuller walk-through of the follow-on risk, see our guide to what happens when your email address turns up in a data breach.
What to do now
None of this requires panic, and most of it has nothing to do with us.
1. Put your passwords in a password manager, and stop reusing them. A leaked password from a forgotten app matters only if it opens something else. For that reason, unique passwords cut the chain. 2. Turn on the strongest sign-in each account offers. For banks and email in particular, that means a passkey or an app-based code rather than a text message. 3. Expect the follow-up scam, and expect it to sound informed. After an exposure like this, the message that arrives quotes something true — your plate, your city, an order you placed. Treat detail as a warm-up, not proof. Then go to the company’s site yourself instead of tapping the link. Then two more, because the Supabase data leak has no notification process behind it.
4. Sign yourself out of old apps. Where an app offers “sign out of all devices,” use it. That is what actually invalidates a stolen token. 5. Watch the small services, not the big ones. The companies in this study are tiny. Because they are tiny, they have no breach-notification team, so the letter may not come at all. We saw the same silence after the Trezor data breach turned into a wave of targeted phishing.
How OptMsg changes this exposure
There are two things here, and both are stated at their real size.
First, your OptMsg account has no password. So when a site you signed up to gets exposed, the pair an attacker ends up holding is your address and that site’s password — and that pair cannot be tried on your inbox, because there is nothing on the account for it to match. Above all, your email is how most other accounts get reset, so keeping that door shut keeps the rest shut with it. That is the security-first case in one sentence, and you can create an OptMsg address in a couple of minutes.
Second, mail from a sender you have not approved goes to Trash, not your Inbox, and it auto-deletes after 30 days. As a result, the follow-up phish dressed as a parking authority lands there. If a lot of other OptMsg users have opted in to a sender, OptMsg flags that message as a Community Recommendation and sends you a push alert, so a real notice in Trash still reaches you.
Here is what that argument does not cover, because overstating it would be worse than saying nothing. It does not undo the exposure at the app — that already happened, somewhere else. Likewise, it does nothing about a compromised device, a live phishing page you type into, or someone holding your unlocked phone. And it does not protect the password you reused on other sites. Rather, the password manager in step one does that job.
Create Your Account
Your Inbox. Your Rules.
Frequently asked questions
Was Supabase hacked in the Supabase data leak? No. Supabase itself was not breached. Researchers found databases hosted on Supabase whose owners left a protective setting switched off, so the tables answered requests from anyone. Supabase says projects are secure by default and that security is shared with the developer.
How do I know if my data was in it? Realistically, you cannot check directly, and that is the hard part of this story. UpGuard did not publish a list of affected apps, and most of the app owners are small teams with no notification process. Act as if an app you signed up for years ago is on the list, and work the steps above.
Which apps were affected? UpGuard described categories rather than names: a US valet parking service, an immigration and relocation firm, an adult streaming site in India, a government consulate’s office in France, and a virtual SIM service used to intercept verification codes. The firm followed responsible-disclosure practice instead of publishing a target list.
Are AI-written apps less safe than other apps? Not inherently. The problem here is narrower. AI tools tend to create tables with raw SQL, and raw SQL leaves Row Level Security off, while the Supabase dashboard switches it on. So the risk comes from a default that differs between two paths, not from the code being AI-written.
Do I need to change my email address? Not for this. But if the same address is the login for dozens of sites, each new exposure adds to the pile. A separate address for accounts you actually care about limits how much any single leak is worth.
Sources
- UpGuard Research, Everything Everywhere: Systemic Data Exposure in Supabase Apps, September 25, 2026 — https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps
- TechCrunch, Some Supabase customers are publicly exposing reams of people’s data to the web, September 25, 2026 — https://techcrunch.com/2026/09/25/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web/
- Cybernews, 16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data, September 25, 2026 — https://cybernews.com/news/16000-supabase-databases-exposed/
Previous in Breach Breakdown: Astrana Health Data Breach: Hackers Called Staff From Astrana's Own Number
Next in Breach Breakdown: Times Car Data Breach: 6.6 Million Accounts, Including License Photos